EC-Council Computer Hacking Forensic Investigator (C|HFI) Training Boot Camp
EC-Council’s C|HFI program prepares cybersecurity professionals with the knowledge and skills to perform effective digital forensics investigations and bring their organization into a state of forensic readiness. Establishing the forensics process, lab, evidence handling procedures and investigation techniques is required to validate and triage incidents and direct the incident response teams. Forensic readiness differentiates between a minor incident and a major cyberattack that brings a company down.
This intense, hands-on digital forensics program immerses students in multiple forensic labs, where they work on crafted evidence files using the tools of the world’s top digital forensics professionals. Students will go beyond traditional hardware and memory forensics, covering current topics in cloud forensics, mobile and IoT, and investigating web application attacks and malware forensics.
What’s new in the C|HFI program
- First certification to offer Dark Web Forensics and IoT Forensics modules
- In-depth focus on volatile and non-volatile data acquisition and examination of Mac Operating Systems and RAM Forensics
- Cloud Forensics methodologies for AWS, Microsoft Azure, and Google Cloud Platform
- Techniques such as defeating anti-forensic methods, Windows ShellBags, analyzing LNK files and Jump Lists
- Malware Forensics process including analysis of latest variants like BlackCat (ALPHV)
- Social Media Forensics and Wireless Network Forensics
- Electron Application and Web Browser Forensics
- In-depth Mobile Forensics Analysis with logical and physical acquisition of Android and iOS devices
- Digital Forensics Investigation through Python Scripting
- 70+ GB of meticulously crafted evidence files for investigation purposes
Recommendations and accreditations:
- National Initiative for Cybersecurity Education (NICE) - 100% compliance with NICE Special Publication 800-181 Cybersecurity Workforce Framework
- ANSI National Accreditation Board (ANAB) - Approved by ANAB (ANSI) ISO/IEC 17024 National Accreditation Board
- U.S. Department of Defense (DoD) - Approved under Directive 8570/8140
- Regulatory Compliance - Covers relevant knowledge bases and skills to meet regulatory compliance standards such as ISO 27001, PCI DSS, SOX, HIPAA, etc.
- Government Communications Headquarters (GCHQ) Certified Training - The C|CISO course meets the standards of the United Kingdom’s GCHQ

What you'll learn
Training overview
- Computer forensics fundamentals, cybercrimes and legal/regulatory standards
- Forensic investigation methodology: documentation, chain of custody and reporting
- Hard disk structures, file systems (NTFS, FAT, ext4, APFS) and storage technologies
- Data acquisition, forensic imaging and eDiscovery processes
- Anti-forensics techniques detection and countermeasures
- Windows forensics: registry, memory, ShellBags, LNK files, Jump Lists and event logs
- Linux and Mac OS forensics and cross-platform investigation techniques
- Network forensics, packet analysis, IOCs and wireless attack investigation
- Malware forensics: static/dynamic analysis and ransomware investigation
- Web application attack investigation and server log analysis
- Dark web forensics: Tor browser artifacts and anonymous communication analysis
- Cloud forensics methodologies for AWS, Azure and Google Cloud Platform
- Email crime investigation and social media forensics
- Mobile forensics: Android/iOS acquisition and SIM file system analysis
- IoT forensics: wearables, smart devices and Amazon Alexa investigations
- Python scripting for forensic automation and analysis
What's included
Everything you need to know
- 90-day extended access to Boot Camp components, including class recordings
- 100% Satisfaction Guarantee
- Exam Pass Guarantee
- Exam voucher
- Knowledge Transfer Guarantee
- Unlimited practice exam attempts
Syllabus
Training schedule
Day 1
Introductions
Computer Forensics in Today’s World
Computer Forensics Investigation Process
Day 2
Hard Disks, File Systems, and Data Acquisition
Anti-forensics Techniques and Windows Forensics
Day 3
Linux and Mac Forensics
Network Forensics
Day 4
Malware Forensics
Web Attacks and Dark Web Forensics
Day 5
Cloud Forensics and Email/Social Media Forensics
Mobile and IoT Forensics
Exam Preparation
Infosec success stories
"The team at Infosec was great from the start, and they were as excited about my journey as I was. They explained the value behind each training I was considering and how it could further my goals. Their enthusiasm was a great motivation throughout the boot camp."
Elle Autumn
EC-Council Certified Ethical Hacking Course: CEH Certification Training Boot Camp Read Elle's Story
"Infosec has uniquely prepared me for any CMMC retraining that will take place inevitably in the future. With them, it’s not just about completing the certification; it's about being a true contributor to the ecosystem."
James Ahern
Certified CMMC Assessor (CCA) Boot Camp Read James's Story
"The hands-on training was the best part. You have an instructor you can actually reach out to and ask questions — not only on the material, but also about things out in the wild with cybersecurity."
Eddie Quinones
CompTIA Security+ Certification Training Boot Camp Read Eddie's Story
"The Infosec CISM Boot Camp gave me the ability to intelligently explain why I'm making a decision. Ultimately, the C-suite is happy and they know, 'Hey, here's a person that we can rely on."
Mohammad Mirza
ISACA Certified Information Security Manager (CISM) Training Boot Camp Read Mohammad's StoryGuaranteed results
Our Boot Camp guarantees
Exam Pass Guarantee
If you don’t pass your exam on the first attempt, get a second attempt for free. Includes the ability to re-sit the course for free for up to one year (does not apply to CMMC-AB Boot Camps).
100% Satisfaction Guarantee
If you’re not 100% satisfied with your training at the end of the first day, you may withdraw and enroll in a different online or in-person course.
Knowledge Transfer Guarantee
If an employee leaves within three months of obtaining certification, Infosec will train a different employee at the same organization tuition-free for up to one year.
What you'll learn
Boot Camp training overview
The C|HFI v11 exam covers 15 module areas:
- Computer Forensics in Today’s World
- Computer Forensics Investigation Process
- Understanding Hard Disks and File Systems
- Data Acquisition and Duplication
- Defeating Anti-forensics Techniques
- Windows Forensics
- Linux and Mac Forensics
- Network Forensics
- Malware Forensics
- Investigating Web Attacks
- Dark Web Forensics
- Cloud Forensics
- Email and Social Media Forensics
- Mobile Forensics
- IoT Forensics
Who should attend
- IT/forensics professionals with basic knowledge of IT/cybersecurity
- Computer forensics and incident response professionals
- Law enforcement personnel and legal professionals
- Security consultants and analysts
- System administrators and network engineers
- DFIR team members
Before your Boot Camp
Prerequisites
Exam Process
How does the C|HFI examination process work?
- Exam Code: 312-49
- Number of Questions: 150
- Duration: 4 hours
- Availability: ECC EXAM Portal
Award-winning training you can trust
Why choose Infosec?
Category
Infosec logo
SANS Institute
Training Camp
Global Knowledge (Skillsoft)
AI-powered, hands-on skill validation
12 Roles
Integrated for all roles
90 days
*Protects your investment if trained employees leave within three months of obtaining certification (Infosec will train a different employee at the same organization tuition-free for up to one year).
Explore our top boot camps